TY - JOUR
T1 - 基于虚拟化航电平台的网络域间安全通信技术
AU - Zhang, Shuang
AU - Kong, Deqi
AU - Wang, Yuanxun
AU - Wan, Xinyu
AU - Yao, Hongjing
AU - Guo, Yangming
N1 - Publisher Copyright:
©2022 Journal of Northwestern Polytechnical University.
PY - 2022/6/1
Y1 - 2022/6/1
N2 - In the information interconnection scenario of the new generation wide-body aircraft, there is a large amount of real-time bi-directional data exchange between aircraft control domain and airline information services domain in civil aircraft avionics system, and its security isolation and information flow protection are facing increasingly serious information security threats. Therefore, a bi-directional secure communication architecture based on virtualization avionics platform is proposed in this study. The attribute-based access control for multiple avionics domain is modeling and the designs of protection for contract security critical data and real-time monitoring for security critical component effectiveness are given. Physical implementation and verification results based on the domestic ACoreOS operating system and avionics hardware platform show that the bi-directional secure communication method based on virtualization avionics platform achieves the spatial isolation of security critical components, the data transmit and receive time of ACD network is less than 50 ms, and the message transmit and receive rate of ACD network is greater than 70 Mb / s. These results can meet the performance requirements of secure communication between avionics network domains of wide-body aircraft, which have high practical value.
AB - In the information interconnection scenario of the new generation wide-body aircraft, there is a large amount of real-time bi-directional data exchange between aircraft control domain and airline information services domain in civil aircraft avionics system, and its security isolation and information flow protection are facing increasingly serious information security threats. Therefore, a bi-directional secure communication architecture based on virtualization avionics platform is proposed in this study. The attribute-based access control for multiple avionics domain is modeling and the designs of protection for contract security critical data and real-time monitoring for security critical component effectiveness are given. Physical implementation and verification results based on the domestic ACoreOS operating system and avionics hardware platform show that the bi-directional secure communication method based on virtualization avionics platform achieves the spatial isolation of security critical components, the data transmit and receive time of ACD network is less than 50 ms, and the message transmit and receive rate of ACD network is greater than 70 Mb / s. These results can meet the performance requirements of secure communication between avionics network domains of wide-body aircraft, which have high practical value.
KW - information flow access control
KW - secure communication between network domains
KW - virtualization avionics platform
KW - wide-body aircraft
UR - http://www.scopus.com/inward/record.url?scp=85139734847&partnerID=8YFLogxK
U2 - 10.1051/jnwpu/20224030530
DO - 10.1051/jnwpu/20224030530
M3 - 文章
AN - SCOPUS:85139734847
SN - 1000-2758
VL - 40
SP - 530
EP - 537
JO - Xibei Gongye Daxue Xuebao/Journal of Northwestern Polytechnical University
JF - Xibei Gongye Daxue Xuebao/Journal of Northwestern Polytechnical University
IS - 3
ER -